Compliance and Reference Standards Notice
Last updated: August 14, 2026 · Version 2.0.0
Sinapsis SpA designs its services and products taking into account applicable Chilean regulation and using international standards as working references. This notice describes which frameworks we use and on what terms.
1. Precise language: what we claim and what we do not
- Yes: we work aligned with the frameworks listed below; we design taking their controls as reference; we prepare documentation and controls compatible with them.
- No: mentioning an ISO standard does not imply formal certification unless expressly stated. As of the date of this notice, Sinapsis SpA holds no current ISO certifications; formal adoption of certifications will be announced publicly.
- No: this notice is neither a declaration of absolute legal compliance nor legal advice to third parties.
2. Chilean regulation considered
- Law No. 21.719 — Personal Data Protection: lawful bases, strengthened data subject rights, security duties, breach notification and the Data Protection Officer (DPO) role, which we have already designated. We adopt its standards ahead of its full entry into force (December 1, 2026). Implementation described in the Privacy Policy and the Personal Data Processing Policy.
- Law No. 19.628 — Protection of Private Life: in force during the regulatory transition.
- Law No. 21.663 — Cybersecurity Framework Law: cybersecurity risk management, incident reporting and business continuity as design criteria. See the Information Security Policy.
- Law No. 20.584 — Patients' Rights and Duties: reinforced regime and retention periods for the health data processed by HumanOS's Care/Health modules.
- Law No. 21.096: constitutional recognition of personal data protection (art. 19 No. 4).
As international best-practice references we also consider the EU GDPR, California's CCPA/CPRA and the NIST Privacy Framework, whose requirements we incorporate where they exceed the local standard.
3. International reference standards
| Standard | Subject | How we use it |
|---|---|---|
| ISO/IEC 27001 | Information security | Reference for access controls, encryption, asset management and the information lifecycle. |
| ISO/IEC 27701 | Privacy and personal data | Reference for managing personally identifiable information and controller/processor roles. |
| ISO/IEC 42001 | AI management systems | Reference for governance, human oversight and risk assessment of AI systems. See the Responsible AI Policy. |
| ISO 22301 | Business continuity | Reference for identifying critical processes, contingency and recovery. |
| ISO 9001 | Quality management | Reference for continuous improvement, process management and client feedback. |
| ISO 31000 | Risk management | Methodological reference for identifying, assessing and treating operational and technological risks. |
| ISO/IEC 27035 | Security incident management | Reference for the detection, containment, notification and learning procedure. See the Security Policy. |
4. How this translates into practice
- Designated DPO (Felipe Mehr — fmehr@sinapsis.in) who oversees compliance and channels the exercise of rights.
- Impact assessments (DPIA) before processing that may pose high risk, and a record of processing activities (RoPA).
- Verifiable policy versioning: each published version is frozen with its SHA-256 fingerprint in an append-only manifest — it can be proven which exact text was in force on any given date.
- Security and privacy are defined at the design stage of every solution, not at the end.
- We document controls, accesses and relevant architecture decisions.
- We assess risks before putting AI systems into operation.
- We maintain a channel for incident reports and the exercise of rights: admin@sinapsis.in.
- We support clients who need to prepare their own documentation and controls against these frameworks.
5. Framework documents
Privacy Policy · Terms and Conditions · Personal Data Processing Policy · Cookie Policy · Information Security Policy · Responsible AI Policy
6. Contact
- Privacy and data subject rights: admin@sinapsis.in
- Security reports: admin@sinapsis.in
- General compliance questions: admin@sinapsis.in